Executive brief
Microsoft Visual Studio contains a heap-based buffer overflow vulnerability that allows an attacker to execute arbitrary code on a user's system over the network. This affects developers and engineering teams who use Visual Studio for software development, potentially compromising their systems and the integrity of code they develop.
Technical details
A heap-based buffer overflow exists in Visual Studio, allowing memory corruption when processing untrusted input. The vulnerability is reachable over the network, enabling remote code execution without requiring user authentication or special privileges. An attacker can exploit this flaw to execute arbitrary code in the context of the Visual Studio process. The vulnerability has been addressed by Microsoft in a security update.
Affected products
- Microsoft Visual Studio
Timeline
- 2026-09-08: disclosed